← Vulnerability feed

Vulnerability record · CVE-2008-0047 · published 18 March 2008

CVE-2008-0047: Cups memory buffer overflow vulnerability

Cups · Cups

Heap-based buffer overflow in the cgiCompileSearch function in CUPS 1.3.5, and other versions including the version bundled with Apple Mac OS X 10.5.2, when printer sharing is enabled, allows remote attackers to execute arbitrary code via crafted search expressions.

9.3 CVSS 2.0 High EPSS 6.8% · top 6.2% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
6.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
52References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in the cgiCompileSearch function in CUPS 1.3.5, and other versions including the version bundled with Apple Mac OS X 10.5.2, when printer sharing is enabled, allows remote attackers to execute arbitrary code via crafted search expressions.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://docs.info.apple.com/article.html?artnum=307562
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=674
http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html Patch
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00005.html
http://secunia.com/advisories/29420 Vendor Advisory
http://secunia.com/advisories/29431 Vendor Advisory
http://secunia.com/advisories/29448 Vendor Advisory
http://secunia.com/advisories/29485 Vendor Advisory
http://secunia.com/advisories/29573 Vendor Advisory
http://secunia.com/advisories/29603 Vendor Advisory
http://secunia.com/advisories/29634 Vendor Advisory
http://secunia.com/advisories/29655 Vendor Advisory
http://secunia.com/advisories/29750 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200804-01.xml
http://www.debian.org/security/2008/dsa-1530
http://www.mandriva.com/security/advisories?name=MDVSA-2008:081
http://www.redhat.com/support/errata/RHSA-2008-0192.html Vendor Advisory
http://www.securityfocus.com/bid/28307
http://www.securitytracker.com/id?1019646
http://www.ubuntu.com/usn/usn-598-1
http://www.us-cert.gov/cas/techalerts/TA08-079A.html US Government Resource
http://www.vupen.com/english/advisories/2008/0921/references Vendor Advisory
http://www.vupen.com/english/advisories/2008/0924/references Vendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10085
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00091.html
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00105.html
http://docs.info.apple.com/article.html?artnum=307562
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=674
http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html Patch
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00005.html
http://secunia.com/advisories/29420 Vendor Advisory
http://secunia.com/advisories/29431 Vendor Advisory
http://secunia.com/advisories/29448 Vendor Advisory
http://secunia.com/advisories/29485 Vendor Advisory
http://secunia.com/advisories/29573 Vendor Advisory
http://secunia.com/advisories/29603 Vendor Advisory
http://secunia.com/advisories/29634 Vendor Advisory
http://secunia.com/advisories/29655 Vendor Advisory
http://secunia.com/advisories/29750 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200804-01.xml

Track CVE-2008-0047 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2015-1158Cups vulnerabilityThe add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-host-name…EPSS 30%10.0CVE-2008-0882Cups memory buffer overflow vulnerabilityDouble free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon crash) and p…EPSS 5.8%10.0CVE-2007-4351Cups vulnerabilityOff-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted (1)…EPSS 7.4%8.8CVE-2018-6553Cups vulnerabilityThe CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape c…EPSS 0.39%8.8CVE-2014-8166Cups improper input validation vulnerabilityThe browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to exe…EPSS 3.7%7.5CVE-2005-4873Cups memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in the phpcups PHP module for CUPS 1.1.23rc1 might allow context-dependent attackers to execute arbitrary code …EPSS 1.9%5.0CVE-2007-0720Cups vulnerabilityThe CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connectio…EPSS 5.3%4.3CVE-2015-1159Cups cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote att…EPSS 7.3%

Source: NIST National Vulnerability Database (record CVE-2008-0047), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.